Nestersoft's vulnerability footprint centers on its WorkTime product, a workforce and time-management application, with the observed exposure spanning web-facing input handling and privilege management weaknesses such as cross-site scripting, OS command injection, SQL injection, and improper access control. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nestersoft over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15559CRITICAL An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server API call to generate and download the WorkTime client from | Feb 19, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-15560HIGH An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpoint to inject SQL queries. If the Firebird backend is used, | Feb 19, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-15561HIGH An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system to NT Authority\SYSTEM. A malicious executable must be named | Feb 19, 2026 | 7.8 | 24 | NO | NO |
CVE-2025-15562MEDIUM The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitr | Feb 19, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-15563MEDIUM Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the WorkTime server. No authorization check is applied here. | Feb 19, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nestersoft.
Media articles that mention a CVE ID that affects a product developed by Nestersoft — matched by CVE ID, not by vendor name.